CV
BEST Program Security Architect
Compu-Vision Consulting Inc.
- 🇺🇸 United States
- Hybrid
- 3 hours ago
- Risk Management
- Disaster Recovery
- Incident Response
- Change Management
- Prism
- SIEM
- IAM
- NIST
- COSO
- FERPA
- GLBA
- Azure Active Directory
- ITIL
- SOX
- COBIT
- Network Security
- DLP
- Jira
- Service Cloud
- Snowflake
3 hours ago
Location: Boton, MA
Duration: 6 MOnths
Position Summary
The BEST Program Security Architect will work for the BEST Solution Technical Lead and Deputy Program Manager
to support the adoption of the future state end user security solution and protocols. Together with the BEST PMO and
BEST Phase 2 Technical Lead, Comptroller Risk Management Team, Product Vendor, Systems Integrator (SI), Office of
the Comptroller, and Executive Office of Technology Services and Security (EOTSS) staff to deploy technical controls to
meet specific end-user security requirements, enable processes and standards to ensure that security configurations are
maintained in the new Human Resource Management and Payroll solution.
As a key member of the project's Security Team, the Risk and Compliance Lead will work closely with other team
members to develop and implement a comprehensive information security program. This includes:
• Design and recommend protocols and procedures for monitoring the product vendor's performance against
Service Level Agreement standards regarding data security, annual security audits, and disaster recovery testing.
• Collect documentation and other artifacts as the project develops to support comprehensive IT and other statewide
audits, which will require documentation of conversion between systems, validation of data, operations and other
content and support data reliability.
• Propose security policies, processes and standards related to end- user roles, data access for application users, and
how users will be provisioned and de-provisioned.
• Provide input on selection, deployment, and oversight of security technologies and other compliance and risk
management/mitigation strategies.
The Risk and Compliance Lead will participate in recommending strategies for:
• Monitoring compliance with vendor and Commonwealth IT security policies and applicable laws.
• Defining procedures for investigating and reporting security incidents.
• Contribute in developing, testing, and documenting security procedures, including disaster recovery, business
continuity, backups, and incident response.
• Monitoring and assessing business continuity and disaster recovery programs, network penetration, and other tests
to assess application vulnerability; and
• Participate in risk and compliance assessment reviews of the new Human Resource and Payroll solution and
supporting services and infrastructure.
• Support of coordinated operational change management strategy to ensure a successful implementation of training
materials, training resources and training opportunities to support compliance with HR Payroll policies and
guidance and successful system change management for users.
The Software as a Solution (SaaS) model chosen by the Commonwealth includes data security protocols and procedures
that are audited annually by a third party. The Service Level Agreement (SLA) and contract documentation between the
Commonwealth and the system integration and product vendor outline the terms and conditions for maintaining data
security, which will be monitored by the Commonwealth. The BEST Risk and Compliance Lead will assist the
Commonwealth in implementing necessary procedures to meet risk mitigation requirements and monitor vendor
compliance with security protocols.
This role involves collaborating with program functional teams to identify end-user roles and permissions for
implementing the new Human Resource and Payroll solution across all agencies and user types, ensuring appropriate data
access. User security procedures will be developed in conjunction with the BEST Phase 2 Technical Lead, Comptroller
Risk Management Team, the system integration and product vendor, and agency staff responsible for user provisioning
and deprovisioning.
In addition this position will coordinate with the BEST program's Independent Verification and Validation (IV &V)
vendor necessary to ensure proper adoption.
This role is responsible for translating complex security problems into sound technical solutions, providing technical
security and architectural direction to technology business teams, ensuring that development efforts are adhering to
security design and compliance standards and requirements, providing insights and guidance on overall secure system
design, and documenting and communicating security architectural requirements.
Specific Duties
This position will oversee implementation of the three major security components:
• Infrastructure (hosting) security
• Application Security
• User Authentication security
Align with BEST project team, vendor, SI, EOTSS security, and Comptroller Risk Management Team, including but not limited to:
o Partner with EOTSS to onboard Workday and Workday Prism to work with the Commonwealth Single
Sign On - SSO for employees and for vendors, as appropriate. For departments, employees, and
contractors that have limitations on the use of the standard EOTSS SSO solution, this roll will assess
options and provide recommendations for how these individuals will be managed and properly secured.
o Assist in the remediation of department user data, as necessary in support of the activities of the CTR
Risk and Compliance Unit.
o Oversee security SLAs with the vendor(s) to ensure appropriate security reports are created, as well as
create a process to for review to ensure SLAs are monitored by the Commonwealth.
o Work with EOTSS on and oversee security and compliance testing / documentation and review/remediate
results/issues, as necessary on collaboration with the Comptroller Risk Management team.
o Work with the BEST technical leadership to develop strategies, procedures and recommended roles and
responsibilities to enforce security requirements and address identified risks related to the use of the new
solution and suitability of underlying internal controls and technologies.
o Provide recommendations regarding end user security roles and groups, data access controls and security
role provisioning (onboarding) and de-provisioning (offboarding) protocols to ensure that data are
accessed appropriately in the new solution in cooperation with the Comptroller Risk Management Team.
o Participate in disaster recovery, business continuity, back up, operational planning, as well as support
disaster recovery/business continuity testing, and documentation.
o Oversee establishment of the overall Security Incident Event Management (SIEM) across several security
operational domains including Cloud SaaS vendor, Comptroller's office, and EOTSS.
o Support the identification, assessment, documentation, prioritization, mitigation, monitoring, and
escalation of program risks.
o Support the program risk register and ensure risks have clearly identified owners, mitigation actions,
target dates, and escalation paths.
o Oversee integration configuration and testing of EOTSS Single Sign On (SSO), EOTSS Identify Access
Management (IAM), EOTSS Multi-Factor Authentication (MFA), Cloud SaaS Vendor user access
management, and Workday access controls and provisioning processes, in cooperation with Comptroller
Risk Management Team.
o Implement agreed mitigations and solutions to address business and technology vulnerabilities.
o Document and implement technical controls, processes and procedures related to data security in
conjunction with the BEST Phase 2 Technical Lead, Assistant Comptroller for Statewide Rick
Management and Compliance, and Commonwealth Executive Office of Technology and Security
Services (EOTSS).
o Assist security administrators and IT staff in the resolution of reported security incidents. Act as a liaison
between incident response leads and subject matter experts. Monitor daily or weekly reports and security
logs for unusual events.
o Translate existing Comptroller Policies, Commonwealth Policies, and EOTSS policies into BEST
program implementation actions, solutions, and processes, as well as on-going operational processes in
cooperation with the Comptroller Risk Management Team and CTR Payroll Teams.
o Assist in identifying security requirements, using methods that may include risk and business impact
assessments.
Components of this activity include but are not limited to:
o Review of SLA requirements agreed to by the Commonwealth and the SI and product vendor(s).
o Review of Commonwealth IT policies related to data security.
o Review of Commonwealth Risk Management Office policies, assessments, and recommendations
regarding data security risk mitigation.
o Conduct additional business system analysis as needed. Design future state security solution supporting
data and application security needs and environment security needs across multiple stakeholders.
o Identify business and technology security vulnerabilities and make recommendations to program
leadership and stakeholders.
o Working with the BEST Phase 2 Technical Lead and Comptroller Risk Management Team, assess
compliance with risk and cybersecurity frameworks and standards such as NIST, ISO, COSO, PCI,
FERPA, and GLBA.
o Assist in the coordination and completion of information security operations documentation.
o Play an advisory role in application development and implementation to assess security requirements and
controls and assist in assuring that security issues are addressed throughout the project life cycle.
o Support the Program and the BEST Phase 2 Technical lead to identify approved end users of the new
solution and coordinate provisioning of users for Day One go live. Drive testing of go live security
solution end-to-end.
o Provide advice to security administrators on normal and exception-based processing of security
authorization requests including the use of system integration or product vendor tools that monitor system
use and data access irregularities.
o Research, evaluate and recommend information-security-related hardware and software, including
developing business cases for security investments.
o Analyze the result of system integration and product vendor audits or audits performed by third parties to
produce recommendations of acceptable risks and risk mitigation strategies regarding security. Provide
recommendations regarding audit finding remediation, including providing feedback and suggestions on
managerial responses to findings, tracking progress and providing status updates to the BEST Team.
o Provide ongoing advice and support to Security operations and IT for incident response, indicators of
compromise (IOC's), vendors security vulnerability notifications, law Enforcement security alerts, etc.
o Maintain an awareness of existing and proposed security-standard-setting groups, state and federal
legislation and regulations pertaining to information security. Identify regulatory changes that will affect
information security policy, standards, and procedures, and recommend appropriate changes.
o Research and assess new threats and security alerts and recommends remedial actions.
o Work with BEST Operations, Comptroller operations, EOTSS operations, and Agency operations to
ensure security operational actions are properly implemented.
o Assist/support BEST Phase 2 Technical Lead on integration data exchange inbound and outbound
requirements identification, definition, and validation.
o Monitor compliance throughout design, configuration, development, testing, deployment, and transition
to operations.
o Execute "tabletop” security reviews of end-to-end go live security processes.
o Oversee and advise BEST program use of AI tools from a security point of view.
o Advise Vendor and SI on use of AI tools that are built into the Workday product natively.
o Ensure the completion of information security operations documentation.
o Develop strategies, procedures and recommended roles and responsibilities to enforce security
requirements and address identified risks related to the use of the new solution.
o Oversee configuration updates and execution role in application development and implementation related
to security requirements and controls, ensures that security controls are implemented as planned and that
security and access needs are addressed throughout the User life cycle in collaboration with the
Comptroller Risk Management Team.
o Provide advise and recommendations to the data conversion of end users from the legacy system to the
new system.
o Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Comptroller's Risk Management Office to
identify, select and implement technical controls related to data security and to implement security
processes and procedures that ensure security controls are managed and maintained both centrally and
within agencies for certain security management tasks are decentralized.
o Advise the BEST Team and SI and product vendors regarding end user security roles and groups, data
access controls and security role provisioning and de-provisioning protocols to ensure that data are
accessed appropriately in the new solution.
o Supports the BEST Team and agencies in the tasks required to identify approved end users of the new
solution and coordinate provisioning of users for Day One go live.
o Advise security administrators on normal and exception-based processing of security authorization
requests including the use of SI or product vendor provided tools that monitor system use and data access
irregularities.
o Act as a liaison between incident response leads and subject matter experts.
o Maintain an awareness of existing and proposed security-standard-setting groups, state and federal
legislation and regulations pertaining to information security. Identifies regulatory changes that will affect
information security policy, standards, and procedures, and recommends appropriate changes.
o Research and assess new threats and security alerts and makes recommendations as necessary.
Supports the implementation of new solution complete security profile, including, but not limited to:
o Azure Active Directory (AD) entry
o Single Sign on (SSO)
o New Solution User Security Role
o New Solution User Workflow Role
Required Skills
• In-depth exposure to technical configurations, technologies, and processing environments in one or more
projects of similar size and complexity to BEST.
• In-depth knowledge and understanding of information risk concepts and principles as a means of relating
business needs to security controls.
• Knowledge of and experience in developing and documenting security architecture and plans, including
strategic, tactical and project plans.
• Documented experience with common information security management frameworks, such as
International Organization for Standardization (ISO) 2700x and the ITIL, SOX, COBIT and National
Institute of Standards and Technology (NIST) frameworks.
• Experience in architecting and implementing cloud-based security solutions.
• Extensive knowledge of security tools and capabilities, such as: IDM and SSO.
• Extensive experience in integrating security tools and 3rd party vendor solutions.
• Exceptional planning, organization, communication, prioritization, and business analysis skills.
• In-depth knowledge of risk assessment methods and technologies.
• Proficiency in performing risk, business impact, control, and vulnerability assessments.
• Excellent technical knowledge of mainstream operating systems and a wide range of security
technologies, such as network security appliances, identity, and access management (IAM) systems, anti
malware solutions, privilege access management (PAM), data loss prevention (DLP), encryption at-rest
and in-transit, multi-factor authentication (MFA), end-point-security, vulnerability scanning and patch
management, automated policy compliance tools, and desktop security tools.
• Experience in developing, documenting, and maintaining security policies, processes, procedures, and
standards.
• Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network
protocols and concepts.
• Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
• Documented written and verbal communication skills.
• Experience working with modern issue tracking systems (JIRA)
• Exposure to technical configurations, technologies, and processing environments in one or more projects
of similar size and complexity to BEST.
• Ability to interact with personnel at all levels and across all business units and organizations, and to
comprehend business imperatives.
Preferred Qualifications
• Extensive experience with Human Resource and Payroll systems security requirements.
• In depth exposure to defining and implementing end user security protocols in a large public or private
sector entity comparable in size to the Commonwealth.
• Experience with AI security
• Experience with implementation of AI tools within a government agency
• Experience with WorkDay Human Resource and Payroll solution, with an additional preference of
implementation within a government agency.
• Experience with WorkDay Prism data and reporting solution.
• Experience with WorkDay user security management as a member of a business (non-IT) team.
• Experience in transitioning traditional IT security functions to business teams.
• Extensive experience with Software-as-a-Service cloud implementations particularly those in which
legacy on premise applications have been migrated to cloud delivery options.
• Experience operating end user security protocols, policies, and other in a large public or private sector
entity comparable in size to the Commonwealth.
• Experience at implementing technical configurations, technologies, and processing environments in one
or more projects of similar size and complexity to BEST.
• Experience with Audit, compliance, or governance actions.
• Experience with Microsoft security tools and functions
• Experience with Snowflake security functions
Minimum Entrance Requirements
• Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of
audit compliance and security risk and compliance management.
• Minimum of nine years of design and implementation experience in IT, with a deep knowledge in a minimum of two
of the following technical disciplines: infrastructure and network design, application development, application
programming interfaces (APIs), middleware, servers and storage, database management, data security, and system
administration and operations
• Experience in generation of Security materials, including but not limited to compliance adherence, security
operational procedures, security implementation plans, and network and security diagrams.
• Minimum of five years of security architecting design and implementation with security certifications, such as: SIA
Security +
BEST Program Security Architect · Compu-Vision Consulting Inc.